- 28 Jun 2024
- 3 Minutes to read
- Print
- DarkLight
- PDF
Role or Entitlement Change Validation Checklist
- Updated on 28 Jun 2024
- 3 Minutes to read
- Print
- DarkLight
- PDF
Before you begin
Verify your downstream applications connected to Clarity are configured correctly
Check the Trust Permission setting for each application
Check each application has an appropriate username rule configured for it
Complete the Role Configuration Checklist
Designate a Role to be used for testing, it's good to have a wide range of applications included in this role for testing purposes.
Create custom “Identity Modified” workflow with a “Condition: Identity Attribute” to limit the scope of the workflow
Use a descriptive name (to help indicate this is for testing, desired scope, etc.)
Add Trigger: Identity Modified
Add Action: Find/Create Identity Role
Add a condition to limit the scope of this workflow (Condition: Identity Attributes or Condition: Identity Roles)
Add Action: Re-Provision Identity
Configure the Action: Re-Provision Identity step in your workflow to match your desired outcome (Deprovision Expiration: never, immediate, custom)
Optional: Add the Action: Push Identity Attributes
Click the blue Save button in the upper right
Create a custom “Under-Provisioned” workflow with a Condition to limit the scope of the workflow to a particular Department, Department and Job Title, or Role, etc.
You may have completed this step already during the Joiners Checklist
Choose a name to indicate this workflow is for testing
Add Trigger: UnderProvisioned Identity Detected
Use a Condition (Identity Attributes or Identity Roles) to limit the scope of the workflow to a particular Department, or Department and Job Title, or Role
Add Action: Provision Identity
Click the blue Save button in the upper right
Modify Existing Identity Modified Workflow (this is to remove provisioning actions for all Identities not included in the scoped workflow above).
Remove Action: Re-Provision Identity
Optional: Remove the Action: Push Identity Attributes
Click the blue Save button in the upper right
Enable your custom Identity Modified workflow
Enable your custom UnderProvisioned Detector workflow
Change the attributes that correspond to your Clarity Organizational Units in your HRIS to trigger someone to change Roles within Clarity
Wait or Sync the above application to trigger Clarity to pull in the changes.
After the sync is complete, refresh your webpage, and search for your Test user
For each application with an associated Entitlement on the new role, check that the downstream Service User has any new entitlements from the new role
For each application with an associated entitlement on the role, check that all of the expected entitlements
Check for Entitlements from the previous role have been successfully removed from the Identity (or receive a proper expiration date).
Re-Enable or add the Re-Provisioning Step to your Identity Modified workflow
Confirm your non-scoped Workflow with Identity Modified Trigger has the Action: Re-Provision Identity correctly configured (Deprovision Expiration: never, immediate, custom)
Re-Enable or remove condition steps from your Under-Provisioned Detector workflow
If you have any problems, contact your customer success team. You can also get in touch with our general support via email, open a support ticket. Our general support team is available Monday - Friday from 8:00 AM - 6:30 PM CST.